4 ms·
Issue is that you don't know which of the tens of thousands of internal IP addresses would correspond to the one or two sysadmins who would have production acc
by taligent 14y ago
Issue is that you don't know which of the tens of thousands of internal IP addresses would correspond to the one or two sysadmins who would have production access.
Which means either the production servers were hacked or there was a widespread compromise of their internal network and systems e.g. email, IM.
- 0x0 14y agoI'm sure more than 2 people at twitter have production access. And identifying the senior staff isn't probably that hard, they probably have quite visible twitter accounts. As someone mentioned in a completely different thread, it'd be enough to have a vulnerable rails running on localhost:3000 on your laptop and "accidentally" being hit with a CSRF, for example. Get a shell on some staffers laptop and stay dormant, I'm sure you'll catch a live ssh session soon enough [with access to that ssh client's process memory] (in fact you'd get quite far just with a copy of the id_rsa + known_hosts files)
- mikegioia 14y agoYea you really only need the contents of ~/.ssh and you could access every server the laptop could. Even if they didn't have production access, a lot of times servers are configured to easily hop from one to another. They could have connected to a development server and then just hopped to the DB server with the accounts it seems they were looking for.